MimesisIQ LLC
Security
How workspaces, tokens, and approvals are kept apart.
Access
Each request is scoped to one workspace. A missing scope fails closed. A workspace token cannot read another tenant. Platform admins can switch into a workspace, and that switch is written to the audit log. An impersonating admin cannot approve a post.
Secrets
Session cookies are signed. Third-party tokens are encrypted at rest with a key derived from the server secret. API tokens are stored as a hash. Stripe and Buffer secrets stay in the host environment, not in the repository.
Posting
Scheduling and live submits check the owner approval gate and the workspace plan. A free workspace can prepare the work. It cannot send it.
Reporting a problem
Email security issues to support@sublimnl.app. We will acknowledge the message and say what we changed.